---
id: CVE-2026-64327
title: >-
  In the Linux kernel, the following vulnerability has been resolved:


  usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction
  checks


  When parsing endpoint descriptors, ffs_data_got_descs() generates the

  eps_addrmap which…
summary: >-
  In the Linux kernel, the following vulnerability has been resolved:


  usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction
  checks


  When parsing endpoint descriptors, ffs_data_got_descs() generates the

  eps_addrmap which…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.9, < 6.12.96'
  - 'linux_kernel >= 6.13, < 6.18.39'
  - 'linux_kernel >= 6.19, < 7.1.4'
  - linux_kernel = 7.2
patched:
  - linux_kernel 7.1.4
published: '2026-07-25'
updated: '2026-09-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64327'
references:
  - url: 'https://git.kernel.org/stable/c/82cf1142e5ccf2b6d6d22ef713aaf3e5f2b5716b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/82cfd4739011bdc7e87b5d585703427e89ddfaa5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9e04055ab5fc0470a0031ee6934739f9aa8f34a5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f99f32ea9aa976afcbec20647ed33b50a52002c1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00159
epssPercentile: 0.05496
ingestedAt: '2026-09-05T13:39:56.246Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks

When parsing endpoint descriptors, ffs_data_got_descs() generates the
eps_addrmap which contains the endpoint direction. However, epfile->in
was previously only populated in ffs_func_eps_enable() which executes
upon USB host connection. As a result, early userspace ioctls like
FUNCTIONFS_DMABUF_ATTACH that run before the host connects would see
epfile->in as 0, leading to incorrect DMA directions.

By moving the initialization to ffs_epfiles_create(), epfile->in is
accurate before userspace opens the endpoint files.

## Affected

- `linux_kernel >= 6.9, < 6.12.96`
- `linux_kernel >= 6.13, < 6.18.39`
- `linux_kernel >= 6.19, < 7.1.4`
- `linux_kernel = 7.2`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.1.4`
